PT-2004-1463 · Zonelabs · Zonealarm+1

Riley Hassell

·

Published

2004-09-01

·

Updated

2017-10-10

·

CVE-2004-0309

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZoneAlarm versions prior to 4.5.538.001 ZoneLabs Integrity client versions prior to 4.0.146.046 ZoneLabs Integrity client 4.5 versions prior to 4.5.085
Description The issue is a stack-based buffer overflow in the SMTP service support in vsmon.exe. This allows remote attackers to execute arbitrary code via a long RCPT TO argument.
Recommendations For ZoneAlarm versions prior to 4.5.538.001, update to version 4.5.538.001 or later. For ZoneLabs Integrity client versions prior to 4.0.146.046, update to version 4.0.146.046 or later. For ZoneLabs Integrity client 4.5 versions prior to 4.5.085, update to version 4.5.085 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0309

Affected Products

Zonealarm
Zonelabs Integrity Client